Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gxq3-h9h6-4fpj

Опубликовано: 24 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 1.6.43 via the hfe_template shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to view the contents of Draft, Private and Password-protected posts they do not own.

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 1.6.43 via the hfe_template shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to view the contents of Draft, Private and Password-protected posts they do not own.

EPSS

Процентиль: 57%
0.00347
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.3
nvd
больше 1 года назад

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 1.6.43 via the hfe_template shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to view the contents of Draft, Private and Password-protected posts they do not own.

EPSS

Процентиль: 57%
0.00347
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200